The Role: The Cybersecurity Analyst will help lead the CMMC compliance efforts to enable pursuit of new GM Defense and other U.S. Government–regulated programs. This role works with cross‑functional teams to execute and assess control implementation, collect and validate audit‑ready evidence, and prepare artifacts for external assessments. The analyst works with the GMD GRC team and leads IT, program management, cloud, and engineering teams to ensure compliance with CMMC, NIST SP 800‑171, DFARS, FAR, and DoD cybersecurity requirements supporting government contracts. The ideal candidate combines strong understanding of security frameworks combined with technical security depth (on-prem + cloud) to manage evidence collection and remediation across multiple internal teams and is capable of obtaining security clearance. What You’ll Do: Drive the overall governance for government programs. Execute annual self-assessments (Continuous Monitoring) on CMMC/NIST controls and document findings. Coordinate internal teams (IAM, cloud, infrastructure, SOC, endpoint, vulnerability management, application owners) to validate control implementation and operational effectiveness. Identify compliance gaps, manage security exceptions (POA&Ms), and drive remediation prior to audit or customer assessments. Lead CMMC readiness and sustainment activities for GM Defense programs, aligned to NIST SP 800‑171 and DoD expectations for CUI protection. Build and maintain assessment‑ready evidence packages (policies, procedures, configurations, logs, tickets, reports) aligned to CMMC and DFARS requirements.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level